VulnSea

CWE-639

CVEs classified under CWE-639, newest first.

531 CVEsRSS

CVE-2026-94494Medium· 5.0
today

jshERP through 3.6 Tenant Information Disclosure via GET /tenant/info

jshERP through 3.6 contains a tenant isolation bypass vulnerability that allows authenticated users to read other tenants' records via the GET /tenant/info endpoint. Attackers can iterate the primary key to enumerate and access sensitive…

Sunlitjishenghua · jshERPvia CVEORG
CVE-2026-94497High· 8.3
today

jshERP through 3.6 Unauthorized Access via by-id Endpoints

jshERP through 3.6 fails to validate object ownership in by-id info, update, and delete endpoints across multiple resource types. Authenticated users can read, modify, and delete other users' business objects by submitting direct object …

Twilightjishenghua · jshERPvia CVEORG
CVE-2026-69190Medium· 6.3
today

Graylog is a free and open log management platform

Graylog is a free and open log management platform. From 6.3.0 until 6.3.14, 7.0.9, and 7.1.4, the view update API for saved searches and dashboards permits a user with edit permission but without entity ownership to include a shareReque…

SunlitGraylog2 · graylog2-servervia NVD
CVE-2026-48826High· 8.1
today

HomeBox is a home inventory and organization system

HomeBox is a home inventory and organization system. Prior to 0.26.0, HandleWipeInventory in backend/app/api/handlers/v1/v1_ctrl_actions.go authorizes POST /v1/actions/wipe-inventory through the global ctx.User.IsOwner value instead of t…

Twilightsysadminsmedia · homeboxvia NVD
CVE-2026-48976High· 8.1
today

HomeBox is a home inventory and organization system

HomeBox is a home inventory and organization system. Prior to 0.26.0, NotifierRepository.Update in backend/internal/data/repo/repo_notifier.go updates a notifier through UpdateOneID(id) without requiring the record's user ID to match the…

Twilightsysadminsmedia · homeboxvia NVD
CVE-2026-48975High· 8.1
today

HomeBox is a home inventory and organization system

HomeBox is a home inventory and organization system. Prior to 0.26.0, MaintenanceEntryRepository.Update and MaintenanceEntryRepository.Delete in backend/internal/data/repo/repo_maintenance_entry.go use UpdateOneID(id) and DeleteOneID(id)…

Twilightsysadminsmedia · homeboxvia NVD
CVE-2026-84298Low· 3.1
today

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.95.3, the V1 DurableTask stream handler stores worker-supplied task_external_id values in the durableInvocations routing map …

Sunlithatchet-dev · hatchetvia NVD
CVE-2026-88978Medium· 4.3
today

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.106.1, the WorkerStatus gRPC polling path in pkg/repository/durable_events.go passes caller-supplied durable task, node, and …

Sunlithatchet-dev · hatchetvia NVD
CVE-2026-55625Medium· 4.9
today

GoCD is a continuous deliver server

GoCD is a continuous deliver server. From 16.1.0 until 26.1.0, the internal material connection test APIs at /go/api/admin/internal/material_test and /go/api/internal/config_repos/*/material_test accept an arbitrary existing pipeline and…

Sunlitvia NVD
CVE-2026-52743Medium· 4.3
today

GoCD is a continuous deliver server

GoCD is a continuous deliver server. Prior to 26.1.0, the internal GoCD UI /jobStatus.json API does not validate that a requested server-assigned job ID belongs to the pipeline and stage named in the request. An authenticated user can gu…

Sunlitgocd · gocdvia NVD
CVE-2025-71420Medium· 4.3PoC
today

UVdesk core-framework before 1.1.7 contains an authorization bypass vulnerability in the saved reply endpoint that allows authenticated agents to access replies restricted to other support groups

UVdesk core-framework before 1.1.7 contains an authorization bypass vulnerability in the saved reply endpoint that allows authenticated agents to access replies restricted to other support groups. Attackers with ROLE_AGENT can enumerate …

Twilightuvdesk · core-frameworkvia NVD
CVE-2026-94382Medium· 4.2PoC
today

Beszel before 0.19.0 contains an insecure direct object reference vulnerability in the POST and DELETE /api/beszel/user-alerts handlers that allows any authenticated user to create or delete alerts on systems they cannot access

Beszel before 0.19.0 contains an insecure direct object reference vulnerability in the POST and DELETE /api/beszel/user-alerts handlers that allows any authenticated user to create or delete alerts on systems they cannot access. Attacker…

Twilighthenrygd · beszelvia NVD
CVE-2026-94393Medium· 6.4
today

When a user creates or edits a report inside an event, MISP can identify an existing report using its UUID without properly checking whether that report actually belongs to the same event. As a result, a user who has editing rights on o…

When a user creates or edits a report inside an event, MISP can identify an existing report using its UUID without properly checking whether that report actually belongs to the same event. As a result, a user who has editing rights on o…

SunlitMISP · MISPvia NVD
CVE-2026-94374High· 8.3
today

MISP contains an insecure direct object reference vulnerability in the processModuleResultsData method of the Event model

MISP contains an insecure direct object reference vulnerability in the processModuleResultsData method of the Event model. When processing module results, the code iterates over EventReport entries supplied in the resolved data and saves…

TwilightMISP · MISPvia NVD
CVE-2026-94152Medium· 4.3
today

A security vulnerability has been detected in Omega Solution FBP Fulfillment by People 2025

A security vulnerability has been detected in Omega Solution FBP Fulfillment by People 2025. This impacts an unknown function of the file /user/ of the component User Profile API. The manipulation of the argument ID leads to authorizatio…

SunlitOmega Solution · FBP Fulfillment by PeopleEPSS 0.22%via NVD
CVE-2026-81652Low· 2.7
yesterday

The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the requesting user is entitled to a given image record before returning it, allowing users with the Contributor role and above to read the sto…

The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the requesting user is entitled to a given image record before returning it, allowing users with the Contributor role and above to read the sto…

SunlitEPSS 0.18%via NVD
CVE-2026-81651Low· 3.1
yesterday

The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the user saving a gallery owns it, allowing any user granted its gallery-management capability by an administrator to overwrite the stored sett…

The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the user saving a gallery owns it, allowing any user granted its gallery-management capability by an administrator to overwrite the stored sett…

SunlitEPSS 0.13%via NVD
CVE-2026-81654Low· 3.1
yesterday

The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not check that a user holds its options capability before saving image sizing settings, allowing users granted only its gallery-management capability by an adm…

The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not check that a user holds its options capability before saving image sizing settings, allowing users granted only its gallery-management capability by an adm…

SunlitEPSS 0.13%via NVD
CVE-2026-81653Medium· 4.2
yesterday

The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the user acting on an image owns the gallery it belongs to, allowing users granted its gallery-management capability by an administrator to del…

The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the user acting on an image owns the gallery it belongs to, allowing users granted its gallery-management capability by an administrator to del…

SunlitEPSS 0.12%via NVD
CVE-2026-93955Medium· 4.3
2d ago

A vulnerability was detected in grimmory-tools grimmory up to 3.3.3/3.4.1

A vulnerability was detected in grimmory-tools grimmory up to 3.3.3/3.4.1. Affected by this vulnerability is the function streamFileToResponse of the file backend/src/main/java/org/booklore/controller/KoboController.java of the component…

Sunlitgrimmory-tools · grimmoryEPSS 0.40%via NVD
CVE-2026-93991High· 7.7
2d ago

Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vulnerability in ListArchivedWorkflows that fails to apply cluster-scoped access review when the metadata.namespace field selector uses the NotEquals operator

Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vulnerability in ListArchivedWorkflows that fails to apply cluster-scoped access review when the metadata.namespace field selector uses the NotEquals operator. A…

Twilightargoproj · argo-workflowsEPSS 0.33%via NVD
CVE-2026-92420Low· 3.8
2d ago

The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.2 does not verify that a booking belongs to the requesting user before modifying or deleting it on two of its booking endpoints, allowing a booking…

The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.2 does not verify that a booking belongs to the requesting user before modifying or deleting it on two of its booking endpoints, allowing a booking…

SunlitEPSS 0.19%via NVD
CVE-2026-92421Medium· 4.7
2d ago

The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.3 does not verify that the host record being modified belongs to the user making the request, allowing authenticated users holding a Hydra Booking …

The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.3 does not verify that the host record being modified belongs to the user making the request, allowing authenticated users holding a Hydra Booking …

SunlitEPSS 0.17%via NVD
CVE-2026-92425Medium· 5.5
2d ago

The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.4 does not perform object-level authorisation checks on several of its host-management operations, allowing users who hold its own administrator-as…

The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.4 does not perform object-level authorisation checks on several of its host-management operations, allowing users who hold its own administrator-as…

SunlitEPSS 0.18%via NVD
CVE-2026-91847Medium· 4.8
2d ago

The Online Scheduling and Appointment Booking System WordPress plugin before 28.2 does not verify that the requester owns the AI booking-assistant conversation named in its unauthenticated conversation actions, allowing any unauthentica…

The Online Scheduling and Appointment Booking System WordPress plugin before 28.2 does not verify that the requester owns the AI booking-assistant conversation named in its unauthenticated conversation actions, allowing any unauthentica…

SunlitEPSS 0.14%via NVD
CVE-2026-89333Medium· 6.5
2d ago

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.0.8 via the 'student_id' parameter due to missing validation on a user co…

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.0.8 via the 'student_id' parameter due to missing validation on a user co…

Sunlitthemeum · Tutor LMS – eLearning and online course solutionEPSS 0.27%via NVD
CVE-2026-76901Medium· 5.8
3d ago

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.4, GET /pool/lead/get/{id} in PoolClueController.get and GET /pool/account/get/{id} in PoolCustomerController.g…

Sunlit1Panel-dev · CordysCRMEPSS 0.33%via NVD
CVE-2026-63647Critical· 9.3PoC
3d ago

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.2, SseController exposes the anonymous /sse/subscribe, /sse/broadcast, and /sse/close endpoints because ShiroFi…

Abyssal1Panel-dev · CordysCRMEPSS 0.47%via NVD
CVE-2026-81182Medium· 4.2
3d ago

SysReptor is a fully customizable pentest reporting platform

SysReptor is a fully customizable pentest reporting platform. Prior to 2026.68, an unauthenticated attacker who holds a public read-write note share link can disclose an uploaded file or image from the same project by updating the shared…

SunlitSyslifters · sysreptorEPSS 0.17%via NVD
CVE-2026-62279High· 7.1
3d ago

LubeLogger is a self-hosted, open-source, web-based vehicle maintenance and fuel mileage tracker

LubeLogger is a self-hosted, open-source, web-based vehicle maintenance and fuel mileage tracker. Prior to 1.6.8, an authenticated user could submit caller-controlled recordIds to the DuplicateRecordsToOtherVehicles endpoint while naming…

Twilighthargata · lubelogEPSS 0.36%via NVD
CWE-639 vulnerabilities (CVEs) · VulnSea